CVE-2021-0644
published 2021-10-06CVE-2021-0644: In conditionallyRemoveIdentifiers of SubscriptionController.java, there is a possible way to retrieve a trackable identifier due to a missing permission check…
PriorityP423medium5.5CVSS 3.1
AVLACLPRLUINSUCHINAN
EPSS
0.11%
1.6th percentile
In conditionallyRemoveIdentifiers of SubscriptionController.java, there is a possible way to retrieve a trackable identifier due to a missing permission check. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11 Android-10Android ID: A-181053462
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| platform | frameworks_base | >= 10:0 < 10:2021-09-01 | 10:2021-09-01 |
| platform | frameworks_base | >= 11:0 < 11:2021-09-01 | 11:2021-09-01 |
| platform | frameworks_opt_telephony | >= 10:0 < 10:2021-09-01 | 10:2021-09-01 |
| platform | frameworks_opt_telephony | >= 11:0 < 11:2021-09-01 | 11:2021-09-01 |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
nvdv2.02.1LOWAV:L/AC:L/Au:N/C:P/I:N/A:N
vendor_redhat3.3LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Android
CVE-2021-0644: Android Security Bulletin 2021-09-01
CVE: CVE-2021-0644
Severity: HIGH
Type: ID
Affected AOSP versions: 10, 11
References: A-181053462
[2]
vendor_android·2021-09-01·CVSS 5.5
CVE-2021-0644 [MEDIUM] CVE-2021-0644: Android Security Bulletin 2021-09-01
CVE: CVE-2021-0644
Severity: HIGH
Type: ID
Affected AOSP versions: 10, 11
References: A-181053462
[2]
Android Security Bulletin 2021-09-01
CVE: CVE-2021-0644
Severity: HIGH
Type: ID
Affected AOSP versions: 10, 11
References: A-181053462
[2]
Red Hat
cups: insecure permissions of /var/log/cups allows for symlink attacks
vendor_redhat·2021-04-29·CVSS 3.3
CVE-2021-25317 [LOW] CWE-276 cups: insecure permissions of /var/log/cups allows for symlink attacks
cups: insecure permissions of /var/log/cups allows for symlink attacks
A Incorrect Default Permissions vulnerability in the packaging of cups of SUSE Linux Enterprise Server 11-SP4-LTSS, SUSE Manager Server 4.0, SUSE OpenStack Cloud Crowbar 9; openSUSE Leap 15.2, Factory allows local attackers with control of the lp users to create files as root with 0644 permissions without the ability to set the content. This issue affects: SUSE Linux Enterprise Server 11-SP4-LTSS cups versions prior to 1.3.9. SUSE Manager Server 4.0 cups versions prior to 2.2.7. SUSE OpenStack Cloud Crowbar 9 cups versions prior to 1.7.5. openSUSE Leap 15.2 cups versions prior to 2.2.7. openSUSE Factory cups version 2.3.3op2-2.1 and prior versions.
It was found that some Linux vendors may assign the ownership of the /
GHSA
GHSA-x87c-8v42-cm55: In conditionallyRemoveIdentifiers of SubscriptionController
ghsa_unreviewed·2022-05-24
CVE-2021-0644 [MEDIUM] CWE-863 GHSA-x87c-8v42-cm55: In conditionallyRemoveIdentifiers of SubscriptionController
In conditionallyRemoveIdentifiers of SubscriptionController.java, there is a possible way to retrieve a trackable identifier due to a missing permission check. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11 Android-10Android ID: A-181053462
OSV
CVE-2021-0644: In conditionallyRemoveIdentifiers of SubscriptionController
osv·2021-09-01
CVE-2021-0644 CVE-2021-0644: In conditionallyRemoveIdentifiers of SubscriptionController
In conditionallyRemoveIdentifiers of SubscriptionController.java, there is a possible way to retrieve a trackable identifier due to a missing permission check. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for exploitation.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2021-10-06
Published